Skip to content

chore(deps): bump docker/login-action from 4 to 4.5.2 (#3929) #1653

chore(deps): bump docker/login-action from 4 to 4.5.2 (#3929)

chore(deps): bump docker/login-action from 4 to 4.5.2 (#3929) #1653

Workflow file for this run

name: Deploy
on:
workflow_dispatch:
push:
branches:
- main
tags:
# pre-release tag
- "202[3-9].[0-9][0-9].[0-9]+-rc[0-9]+"
# release tags
- "202[3-9].[0-9][0-9].[0-9]+"
defaults:
run:
shell: bash
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: write
id-token: write
packages: write
pull-requests: write
jobs:
setup:
runs-on: ubuntu-latest
outputs:
env_name: ${{ steps.set-env.outputs.env_name }}
is_tag: ${{ steps.set-env.outputs.is_tag }}
is_release: ${{ steps.set-env.outputs.is_release }}
steps:
- id: set-env
run: |
# 1. Determine if it's a tag
if [[ "${{ github.ref_type }}" == "tag" ]]; then
IS_TAG="true"
else
IS_TAG="false"
fi
echo "is_tag=$IS_TAG" >> $GITHUB_OUTPUT
# 2. Determine environment name
if [[ $IS_TAG == "false" ]]; then
ENV="dev"
elif [[ "${{ github.ref }}" == *"-rc"* ]]; then
ENV="test"
else
ENV="prod"
fi
echo "env_name=$ENV" >> $GITHUB_OUTPUT
# 3. Determine if it's a final release tag
if [[ $ENV == "prod" ]]; then
echo "is_release=true" >> $GITHUB_OUTPUT
else
echo "is_release=false" >> $GITHUB_OUTPUT
fi
tests-ui:
needs: [setup]
uses: ./.github/workflows/tests-ui.yml
if: ${{ needs.setup.outputs.is_tag == 'true' }}
tests-pytest:
needs: [setup]
uses: ./.github/workflows/tests-pytest.yml
if: ${{ needs.setup.outputs.is_tag == 'true' }}
check-migrations-and-messages:
needs: [setup]
uses: ./.github/workflows/check-migrations-and-messages.yml
if: ${{ needs.setup.outputs.is_tag == 'true'}}
check-dynamic-version:
needs: [setup]
uses: ./.github/workflows/check-dynamic-version.yml
if: ${{ needs.setup.outputs.is_tag == 'true' }}
deploy:
runs-on: ubuntu-latest
needs:
[
setup,
tests-ui,
tests-pytest,
check-migrations-and-messages,
check-dynamic-version,
]
if: (!cancelled())
environment: ${{ needs.setup.outputs.env_name }}
steps:
- name: Checkout
uses: actions/checkout@v7
- uses: actions/setup-python@v7
with:
python-version-file: .github/workflows/.python-version
cache: pip
cache-dependency-path: "**/pyproject.toml"
- name: Write python packages to file
run: |
python -m venv .venv
source .venv/bin/activate
pip install pipdeptree
pip install -e .
pipdeptree
pipdeptree >> benefits/static/requirements.txt
- name: Write commit SHA to file
run: echo "${{ github.sha }}" >> benefits/static/sha.txt
- name: Docker Login to GitHub Container Registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@v4
- name: Cache Parameters
id: cache_params
run: |
CACHE_SCOPE="cal-itp"
MAIN_BRANCH_REF="refs/heads/main"
echo "cache_from_args=type=gha,scope=${CACHE_SCOPE},ref=${MAIN_BRANCH_REF}" >> $GITHUB_OUTPUT
echo "cache_to_args=type=gha,scope=${CACHE_SCOPE},mode=max,ref=${MAIN_BRANCH_REF}" >> $GITHUB_OUTPUT
- name: Build, tag, and push image to GitHub Container Registry
uses: docker/build-push-action@v7
with:
builder: ${{ steps.buildx.outputs.name }}
build-args: GIT-SHA=${{ github.sha }}
cache-from: ${{ steps.cache_params.outputs.cache_from_args }}
cache-to: ${{ steps.cache_params.outputs.cache_to_args }}
context: .
file: appcontainer/Dockerfile
push: true
tags: ghcr.io/${{ github.repository }}:${{ github.sha }}
# deploy application service
- name: Deploy to Azure Web App
uses: azure/webapps-deploy@v2
with:
app-name: ${{ vars.AZURE_WEBAPP_NAME }}
images: ghcr.io/${{ github.repository }}:${{ github.sha }}
publish-profile: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }}
# begin setup to deploy container app
- name: Log in to azure using federated identity credentials
uses: azure/login@532459ea530d8321f2fb9bb10d1e0bcf23869a43 # v3
with:
client-id: ${{ secrets.AZURE_SP_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
- name: Setup terraform
uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4
with:
terraform_version: 1.15.8 # should match TF_VERSION in .devcontainer/Dockerfile
- name: Initialize terraform and select workspace
working-directory: terraform
run: ./init.sh "${{ needs.setup.outputs.env_name }}"
- name: Terraform plan
working-directory: terraform
env:
TF_VAR_CONTAINER_TAG: ${{ github.sha }}
TF_VAR_DEVSECOPS_OBJECT_ID: ${{ secrets.TF_VAR_DEVSECOPS_OBJECT_ID }}
TF_VAR_ENGINEERING_GROUP_OBJECT_ID: ${{ secrets.TF_VAR_ENGINEERING_GROUP_OBJECT_ID }}
TF_VAR_sp_apply_object_id: ${{ secrets.AZURE_SP_OBJECT_ID }}
TF_VAR_sp_plan_object_id: ${{ secrets.AZURE_SP_PLAN_OBJECT_ID }}
run: terraform plan -out=tfplan -lock-timeout=5m
- name: Terraform apply
working-directory: terraform
run: terraform apply -lock-timeout=5m tfplan
# attach a detailed summary directly to a gh actions job. sensitive values that match repo secrets are automatically redacted
- name: Attach detailed summary to job
uses: borchero/terraform-plan-comment@f585438eda2fa77c6f275994b92aeccd86ef3542 # v3.2.0
with:
planfile: tfplan
token: ${{ github.token }}
skip-comment: true
working-directory: terraform
release:
needs: deploy
if: ${{ needs.setup.outputs.is_release =='true' }}
runs-on: ubuntu-latest
permissions:
# https://github.com/softprops/action-gh-release#permissions
contents: write
steps:
- name: Checkout
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Release
uses: softprops/action-gh-release@v3
with:
prerelease: false
generate_release_notes: true